First published: Wed Feb 07 2024(Updated: )
Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR.
Credit: help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Leanote | =2.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0849 is classified as a high severity vulnerability due to its potential for arbitrary file access.
To remediate CVE-2024-0849, upgrade the Leanote Desktop application to a version that is not affected by this vulnerability.
CVE-2024-0849 specifically affects the Leanote Desktop application version 2.7.0.
CVE-2024-0849 allows an attacker to access arbitrary local files on the affected system.
CVE-2024-0849 is specific to version 2.7.0 of Leanote Desktop; therefore, other versions may not be affected.